Description
An issue was discovered in SpecialEditGrowthConfig in the GrowthExperiments extension in MediaWiki through 1.36.2. The growthexperiments-edit-config-error-invalid-title MediaWiki message was not being properly sanitized and allowed for the injection and execution of HTML and JavaScript.
Remediation
References
Related Vulnerabilities
osTicket Other Vulnerability (CVE-2005-1436)
WebLogic CVE-2019-2888 Vulnerability (CVE-2019-2888)
WordPress Plugin CiviCRM Multiple Cross-Site Scripting Vulnerabilities (5.35.0)
MySQL CVE-2022-21336 Vulnerability (CVE-2022-21336)
WordPress Plugin Gutenberg Block Editor Toolkit-EditorsKit Remote Code Execution (1.31.5)